• Full Time
  • Lagos

Wema Bank Plc

Incident Response Officer Job at Wema Bank Lagos

Wema Bank is hiring a Monitoring and Incident Response Officer in Lagos with 0–2 years of cybersecurity, SOC, incident response or IT experience.

Job Overview

Wema Bank Plc is recruiting a Monitoring and Incident Response Officer for its Security Operations Centre in Lagos. The officer will monitor the bank’s security environment, detect potential cybersecurity threats and support the investigation and management of security incidents.

The role involves reviewing security alerts, analysing logs, investigating suspicious activity and helping contain threats that could affect the organisation’s cloud or on-premises infrastructure. The successful candidate will work with technologies such as SIEM, EDR, Microsoft Sentinel, CyberArk Privileged Access Management, Active Directory and Microsoft Entra ID.

Applicants should possess a bachelor’s degree in Information Security, Computer Science, Information Technology, Cybersecurity or a related discipline. The position requires zero to two years of relevant experience and includes participation in shift-based, 24-hour Security Operations Centre coverage.

Job Details

About Wema Bank Plc

Wema Bank Plc is an indigenous Nigerian bank that provides banking and financial-advisory services to members of the Nigerian public. The supplied company information describes it as Nigeria’s longest-surviving indigenous bank.

Key Responsibilities

Security Monitoring

The Monitoring and Incident Response Officer will continuously monitor security alerts and events generated by:

  • Security Information and Event Management systems.
  • Endpoint Detection and Response tools.
  • Privileged Access Management systems.
  • Microsoft Sentinel.
  • Other cybersecurity-monitoring platforms used by the organisation.

The officer will review available data to identify unusual behaviour, potential threats and indicators of compromise.

Incident Investigation and Triage

The successful candidate will investigate suspected cybersecurity incidents by:

  • Reviewing and triaging security alerts.
  • Determining the possible severity and impact of an incident.
  • Investigating phishing attempts.
  • Examining suspected malware activity.
  • Reviewing other suspicious events or behaviour.
  • Identifying matters that require immediate escalation or containment.
  • Following established incident-response processes and playbooks.

Incident Response

The role includes supporting the different stages of security-incident response. Responsibilities will cover:

  • Analysing identified incidents.
  • Taking appropriate containment actions.
  • Supporting the eradication of threats.
  • Assisting with system and operational recovery.
  • Isolating affected endpoints when required.
  • Escalating incidents through the approved channels.
  • Working with relevant teams to support remediation.

Log and Security Event Analysis

The officer will analyse logs and events from:

  • Operating systems.
  • Business and technical applications.
  • Network devices.
  • Cloud platforms.
  • Security-monitoring systems.

This analysis will be used to identify possible threats, understand incident activity and support response decisions.

Privileged Access Monitoring

The successful candidate will support monitoring activities involving CyberArk Privileged Access Management by:

  • Reviewing privileged-user activity.
  • Investigating unusual or suspicious privileged access.
  • Supporting inquiries involving potentially compromised accounts.
  • Escalating identified concerns according to established procedures.

Threat Intelligence

The Monitoring and Incident Response Officer will use threat-intelligence resources to strengthen detection and response activities. This will involve:

  • Reviewing relevant threat-intelligence feeds.
  • Applying the MITRE ATT&CK framework where appropriate.
  • Identifying indicators of compromise.
  • Supporting improvements to security-monitoring and detection methods.
  • Contributing information that can help the Security Operations Centre respond to emerging threats.

Cloud and On-Premises Security

The role covers monitoring across both cloud-based and on-premises environments. The successful candidate will help protect systems associated with:

  • Microsoft Entra ID.
  • Active Directory.
  • End-user devices.
  • Cloud platforms.
  • Internal infrastructure.
  • Relevant network and application environments.

Incident Documentation and Reporting

The officer will maintain accurate records of security investigations by:

  • Documenting incident findings.
  • Recording identified root causes.
  • Describing containment and response measures taken.
  • Capturing lessons learned from resolved incidents.
  • Maintaining incident records and SOC reports.
  • Updating security dashboards and performance metrics.

SOC Process Improvement

The successful candidate will contribute to the continuing development of cybersecurity operations by:

  • Assisting with new security-monitoring use cases.
  • Helping improve alert rules.
  • Supporting updates to incident-response procedures.
  • Identifying opportunities to strengthen threat detection.
  • Applying lessons from previous incidents to future monitoring activities.

Cross-Functional Collaboration

The officer will work with relevant teams during security investigations and remediation activities, including:

  • Information Technology.
  • Infrastructure.
  • Risk.
  • Compliance.
  • Relevant business teams.

Qualifications and Experience

Applicants should possess:

  • A bachelor’s degree in Information Security, Computer Science, Information Technology, Cybersecurity or a related field.
  • Zero to two years of experience in a Security Operations Centre, Information Security, Incident Response, IT Operations or Cybersecurity.
  • Experience gained within a financial institution or another regulated environment, as stated in the vacancy.
  • Availability to participate in shift-based 24×7 Security Operations Centre coverage.

Preferred Professional Certifications

Any of the following certifications will be an advantage:

  • Blue Team Level 1.
  • Hack The Box Certified Defensive Security Analyst.
  • Microsoft Security Operations Analyst Associate (SC-200).
  • CompTIA Cybersecurity Analyst (CySA+).
  • CompTIA Security+.

These certifications are preferred rather than mandatory.

How to Apply

Interested and qualified candidates should review the role requirements carefully and submit their application through Wema Bank Plc’s official recruitment platform using the Apply button on this page. Applications must be submitted by 31 August 2026.

To apply for this job please visit wemabank.seamlesshiring.com.

Scroll to Top
Verified by MonsterInsights